PoC Index

CVE-2015-3224

MEDIUM 4.3EPSS 44.7%

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
44.71% chance of exploitation in the next 30 days, 99th percentile
Nuclei
medium · CWE-284
Published
2015-07-26
Updated
2024-08-06

Proof-of-concept exploits (7)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related